Implement IaC scanning in CI pipelines
Implementation Effort: Medium – Enabling Defender for Cloud, connecting the DevOps connector, and adding Microsoft Security DevOps scanning with SARIF upload spans security and pipeline teams.
User Impact: Low – IaC scanning runs in the build and reports findings to reviewers; end users are not affected.
Lifecycle Stage: Build